Impact
The Master Blocks WordPress plugin, versions 1.4.1 through 1.4.1.4, contains a REST route that lacks authorization checks. An unauthenticated visitor can use this route to modify the plugin’s white‑label setting, which the plugin then outputs unescaped in the admin area. When an administrator visits a wp‑admin page, the injected script runs with the administrator’s privileges, allowing arbitrary JavaScript execution in that context. The vulnerability directly compromises the confidentiality and integrity of the administrator session.
Affected Systems
The affected product is the Master Blocks plugin for WordPress, specifically versions 1.4.1 through 1.4.1.4. All releases before 1.5.0 are unpatched and vulnerable to this issue.
Risk and Exploitability
The flaw can be exploited by any visitor who can reach the site, as authentication is not required. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, so the exact likelihood of exploitation is unknown. The vulnerability provides privilege escalation to an administrator’s session. Sites that host the Master Blocks plugin and expose a public WordPress site are at risk of an attacker injecting and executing malicious code with administrative privileges.
OpenCVE Enrichment